SafePay Ransomware Group
Threat Actor
SafePay is a relatively new but highly active ransomware operation known for using a "double extortion" tactic—encrypting victims' files while also stealing their data and threatening to leak it. The group gains initial access to corporate networks using compromised credentials for VPN gateways.
Incidents Associated with this Threat
Malware Used by this Threat Actor
No malware identified for this threat actor.
